CVE-2004-0095
McAfee ePolicy Orchestrator - Denial of Service and Possible Remote Code Execution via Invalid HTTP Content-Length
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0095. PoCs published by cyber_flash.
AI-analyzed exploit summary This PoC exploits a buffer management vulnerability in McAfee ePolicy Orchestrator Agent by sending a malformed HTTP POST request with a negative Content-Length header, potentially causing a crash or buffer overflow.
Description
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
Exploits (1)
This PoC exploits a buffer management vulnerability in McAfee ePolicy Orchestrator Agent by sending a malformed HTTP POST request with a negative Content-Length header, potentially causing a crash or buffer overflow.